Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

893 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.71%—Withsecure Client SecurityAIWithsecure Server SecurityAIWithsecure Email AND Server SecurityAIWithsecure Elements Endpoint ProtectionAI+526/2/202417/6/2026
Certain WithSecure products allow a Denial of Service because the engine scanner can go into an infinite loop when processing an archive file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later,…
ModificadaMedia (6.1)0.47%—Zalify Easy Email9/2/202417/6/2026
Cross Site Scripting (XSS) vulnerability in EasyEmail v.4.12.2 and before allows a local attacker to execute arbitrary code via the user input parameter(s). NOTE: Researcher claims issue is present in all versions prior and later than tested version.
ModificadaMedia (6.7)0.17%—Withsecure Client SecurityWithsecure Server SecurityWithsecure Email AND Server SecurityWithsecure Elements Endpoint Protection8/2/202417/6/2026
Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15 and later, WithSecure Server Security 15 and later, WithSecure Email and Server Security 15 and later, and WithSecure Elements Endpoint Protection 17 and later.
ModificadaAlta (7.2)1.2%💥 PoCRemyandrade Login System With Email Verification29/1/202417/6/2026
Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.
ModificadaMedia (4.8)0.40%—Benaceur-php Restrict Usernames Emails Characters29/1/202417/6/2026
The Restrict Usernames Emails Characters WordPress plugin before 3.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
ModificadaAlta (7.5)1.2%—Ypopsemail Ypops!29/1/202417/6/2026
The POP3 service in YahooPOPs (aka YPOPs!) 1.6 allows a remote denial of service (reboot) via a long string to TCP port 110, a related issue to CVE-2004-1558.
ModificadaMedia (6.5)0.40%—Zorem Sales Report Email FOR Woocommerce17/1/202417/6/2026
Missing Authorization vulnerability in Zorem Sales Report Email for WooCommerce.This issue affects Sales Report Email for WooCommerce: from n/a through 2.8.
ModificadaMedia (5.4)0.40%—Onlineoptimisation Email Encoder11/1/202422/7/2026
The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's eeb_mailto shortcode in all versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
ModificadaCrítica (9.8)0.71%💥 PoCCisco Ironport Email Security ApplianceCisco Secure Email Gateway Firmware10/1/202417/6/2026
Hyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.2647), as used in Cisco IronPort Email Security Appliance Software, Cisco Secure Email Gateway, and various non-Cisco products, allow attackers to trigger a segmentation fault and execute arbitrary code via a crafted document.
ModificadaCrítica (9.8)0.57%—Soxft Timemail9/1/202417/6/2026
A vulnerability, which was classified as critical, has been found in soxft TimeMail up to 1.1. Affected by this issue is some unknown functionality of the file check.php. The manipulation of the argument c leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this…
ModificadaMedia (6.1)0.44%—I13websolution Email Subscription Popup8/1/202417/6/2026
The Email Subscription Popup WordPress plugin before 1.2.20 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (5.3)0.43%—Sumanbhattarai Send Users Email5/1/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Suman Bhattarai Send Users Email.This issue affects Send Users Email: from n/a through 1.4.3.
ModificadaBaja (3.3)0.20%—Samsung Email4/1/202417/6/2026
Implicit intent hijacking vulnerability in Samsung Email prior to version 6.1.90.16 allows local attacker to get sensitive information.
ModificadaMedia (4.8)0.33%—Zerobounce Email Verification & Validation29/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZeroBounce ZeroBounce Email Verification & Validation allows Stored XSS.This issue affects ZeroBounce Email Verification & Validation: from n/a through 1.0.11.
ModificadaCrítica (9.8)45%💥 ExploitBarracuda Email Security Gateway 300 FirmwareBarracuda Email Security Gateway 400 FirmwareBarracuda Email Security Gateway 600 FirmwareBarracuda Email Security Gateway 800 Firmware+124/12/202317/6/2026
Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Appliance, from 5.1.3.001 through 9.2.1.001, until Barracuda removed the vulnerable logic.
ModificadaAlta (7.5)0.55%—Winwar WP Email Capture21/12/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Winwar Media WordPress Email Marketing Plugin – WP Email Capture.This issue affects WordPress Email Marketing Plugin – WP Email Capture: from n/a through 3.10.
ModificadaMedia (5.4)0.40%—Tillkruss Email Address Encoder15/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Till Krüss Email Address Encoder allows Stored XSS.This issue affects Email Address Encoder: from n/a through 1.0.22.
ModificadaMedia (4.8)0.46%—Codepeople Contact Form Email11/12/202317/6/2026
The Contact Form Email WordPress plugin before 1.3.44 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (6.1)0.37%—I13websolution Email Subscription Popup6/12/202317/6/2026
The Email Subscription Popup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the HTTP_REFERER header in all versions up to, and including, 1.2.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
ModificadaMedia (5.3)0.62%—Gopiplus Email Download Link30/11/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gopi Ramasamy Email download link.This issue affects Email download link: from n/a through 3.7.
ModificadaAlta (7.5)0.67%—Gopiplus Email Posts TO Subscribers30/11/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gopi Ramasamy Email posts to subscribers.This issue affects Email posts to subscribers: from n/a through 6.2.
ModificadaMedia (6.1)0.43%—Sophos Email Appliance30/11/202317/6/2026
A reflected XSS vulnerability allows an open redirect when the victim clicks a malicious link to an error page on Sophos Email Appliance older than version 4.5.3.4.
ModificadaAlta (7.5)0.70%—F-secure Linux ProtectionF-secure Linux Security 64F-secure AtlantF-secure Client Security+327/11/202317/6/2026
Certain WithSecure products allow a Denial of Service because there is an unpack handler crash that can lead to a scanning engine crash. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure…
ModificadaMedia (5.3)0.61%—F-secure Linux ProtectionF-secure Linux Security 64F-secure AtlantF-secure Client Security+327/11/202317/6/2026
Certain WithSecure products allow a Denial of Service because scanning a crafted file takes a long time, and causes the scanner to hang. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure…
ModificadaAlta (7.5)0.55%—Omnisend Email Marketing FOR Woocommerce23/11/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Omnisend Email Marketing for WooCommerce by Omnisend.This issue affects Email Marketing for WooCommerce by Omnisend: from n/a through 1.13.8.
Orbitaley — Vulnerabilidades